GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   DDoS attacks on 21sextury servers (https://gfy.com/showthread.php?t=738982)

Jace 06-02-2007 04:46 PM

DDoS attacks on 21sextury servers
 
Just got this

Quote:

Dear partners,

as you probably noticed, our sites and affiliate system is hardly accessible these days as we are under continuous DDoS attacks. We solve one thing and another comes immediately. We do our best to keep the bad guys outside but it is not easy... they start new attacks on other fronts again and again.

Existing memberships and rebills are mostly working, signups are hardly working and the affiliate system is not accessible all the time and from all locations.

Once we'll be working stable again, we'll compensate every one of our affiliates for the recent days' losses.
We are sorry for all inconveniences it causes.
Thank you for your patience!

Kind regards,
21sextury Cash staff

Jace 06-02-2007 04:47 PM

BTW....21sexturycash guys, if you read this, and your network is truly that important....go here www.prolexic.com

maddox 06-02-2007 04:55 PM

Quote:

Originally Posted by Jace (Post 12532719)
BTW....21sexturycash guys, if you read this, and your network is truly that important....go here www.prolexic.com

prolexic is bullshit, any serious botnet owner can crush them, search google carefully

PR_Sebas 06-02-2007 07:03 PM

yah i got that email too... sux for them, hopefully they get everything straightened out

Screaming 06-02-2007 07:46 PM

sucks for them...

gero 06-03-2007 03:04 AM

Thank you for the info on prolexic, we saw that already, but it doesn't really help on the attacks we get. There is an another thread related to this issue. I can't post it here, as I don't have enough posts yet. So if you are interested please search 21sextury, and the thread will show up in the top3 results

Jace 06-03-2007 03:15 AM

i don't see how the largest ddos prevention company in the world can't help you?

everblazin 06-03-2007 03:19 AM

Depends what kind of ddos attack it is probrably

Jace 06-03-2007 03:24 AM

ah, ok, I see now, this isn't a "classic" DDOS, this is basically a nats based attack

gero 06-03-2007 04:04 AM

anyways, we are trying to find a solution, whatever way works

Brad Mitchell 06-03-2007 05:06 AM

Best of luck with your problem. :/


Brad

Marshal 06-03-2007 05:52 AM

change your ISP and host your servers with trusted hosting that can filter out DDoS on hardware level. you can see sig, or find something yourself. :)

gero 06-03-2007 12:08 PM

Quote:

Originally Posted by nettrust (Post 12535171)
change your ISP and host your servers with trusted hosting that can filter out DDoS on hardware level. you can see sig, or find something yourself. :)

The problem is not a ddos by itself. The problem is that they attack NATS specific codes.

riddler 06-03-2007 12:16 PM

Quote:

Originally Posted by nettrust (Post 12535171)
change your ISP and host your servers with trusted hosting that can filter out DDoS on hardware level. you can see sig, or find something yourself. :)

with the right sized botnet you can cripple pretty much any network of sites.

Roald 06-03-2007 12:21 PM

Quote:

Originally Posted by Jace (Post 12534508)
ah, ok, I see now, this isn't a "classic" DDOS, this is basically a nats based attack

How does that work in n00b language?

Masterchief 06-03-2007 12:24 PM

Quote:

Originally Posted by QuaShe (Post 12536676)
How does that work in n00b language?

they're attacking flaws in the NATS software itself

Roald 06-03-2007 12:32 PM

Quote:

Originally Posted by Masterchief (Post 12536692)
they're attacking flaws in the NATS software itself

So this is a problem everybody using NATS can walk into?

TMM_John 06-03-2007 12:44 PM

Gero, please contact me asap. ICQ: 5596373 or AIM JohnA1078, or by phone tomorrow after 10am EST, 732-385-1536 x111.

Roald 06-03-2007 12:48 PM

Quote:

Originally Posted by QuaShe (Post 12536744)
So this is a problem everybody using NATS can walk into?

Quote:

Originally Posted by PBucksJohn (Post 12536781)
Gero, please contact me asap. ICQ: 5596373 or AIM JohnA1078, or by phone tomorrow after 10am EST, 732-385-1536 x111.

Is that a yes?

TMM_John 06-03-2007 12:55 PM

Quote:

Originally Posted by QuaShe (Post 12536789)
Is that a yes?

No.

5678

gero 06-03-2007 01:14 PM

Anyways about NATS, to make it clear, I didn't say and don't want to be interpreted as I said that it's the problem of the software why we are down.

gero 06-03-2007 01:21 PM

Sorry if it was misunderstanding for anybody on NATS.

Roald 06-03-2007 01:28 PM

Quote:

Originally Posted by gero (Post 12536879)
Anyways about NATS, to make it clear, I didn't say and don't want to be interpreted as I said that it's the problem of the software why we are down.

It was called a NATS based attack so thats what made me wonder, not asuming anything man.

Good luck with the attack hope it gets resolved quickly!

DamageX 06-03-2007 01:42 PM

Quote:

Originally Posted by QuaShe (Post 12536744)
So this is a problem everybody using NATS can walk into?

Everyone using any kind of php/mysql-based software can run into such issues, NATS included.

TheSenator 06-03-2007 01:51 PM

Quote:

Originally Posted by DamageX (Post 12536972)
Everyone using any kind of php/mysql-based software can run into such issues, NATS included.

True...

NATS should be able to profile this kind of attack since the code is on their servers.

gero 06-03-2007 02:46 PM

Quote:

Originally Posted by TheSenator (Post 12537005)
True...

NATS should be able to profile this kind of attack since the code is on their servers.

Bro, it's not a fault coming from NATS. It could be whatever software you use.

SmokeyTheBear 06-03-2007 02:51 PM

Quote:

Originally Posted by gero (Post 12537296)
Bro, it's not a fault coming from NATS. It could be whatever software you use.

thats not what he is saying he is saying nats should be able to help isolate the problem as it IS being used.

Just curious what brought this about , usually its when a mailer doesnt get paid..:winkwink:

kaori 06-03-2007 03:07 PM

Quote:

Originally Posted by SmokeyTheBear (Post 12537336)
thats not what he is saying he is saying nats should be able to help isolate the problem as it IS being used.

Just curious what brought this about , usually its when a mailer doesnt get paid..:winkwink:

hahah - yeah, like this guy?? Spam I found in my email box today...

Quote:

from Headley Osgood <[email protected]>
to
date Jun 2, 2007 7:12 AM
subject a large nail beat out screams from Yvonne
signed-by gmail.com
http://www.teachmefisting.com

Exclusivity
100&#37; EXCLUSIVE

Category
fisting and pissing fetish

Niche
amateur, teen, hardcore, fisting, pissing, speculum, extreme objects,
pussy closeup

Description:
What do we have in here? Horny sluts who test their pussies with
extreme objects, wide-open speculums and each other's full fists! The
title says it all: our teachers teach them how to fist and how to get
fisted! These girls are not afraid to try it out and oh boy, how much
do they enjoy it at the end! Their young innocent pussies were
destined to receive a thorough fisting, that's for sure!

Extra feature
The cutest babes receive the pussy stretching they won't ever

Updates
site is updated daily, new episodes added every week, both photos and videos

SmokeyTheBear 06-03-2007 03:13 PM

Quote:

Originally Posted by kaori (Post 12537418)
hahah - yeah, like this guy?? Spam I found in my email box today...

lol your one step ahead of me i was just gonna go look in my inbox and see if i had spam from them, that usually explains it..


once you get in bed with these guys its hard to get back out of bed , especially when your holding the loot lol

anyways hopefully the problems get fixed , and hopefully people/sponsors will take this thread in mind .. if you deal with unethical people or in an unethical manner it comes back to bite you in the ass.

Now this whole thing might just be coincidence , but when a sponsor is getting ddos its usually mailers and they usually have a reason :)

lets hope this is an isolated problem

tranza 06-03-2007 03:34 PM

That's no good... I hope they can solve their problems soon...

zargan 06-03-2007 03:49 PM

Quote:

Originally Posted by Jace (Post 12532711)
Just got this


DDOS at the application level or network level ? ... it is a BIG difference because 21sextury cash can stop the application level attacks but if there it is a network attack only ISP should stop this

Phil21 06-03-2007 03:53 PM

I call bullshit on 'prolexic can't help'. They filter application-level attacks as part of their business, otherwise they would be completely worthless. It is EXTREMELY rare to find a simple "massive" ddos attack any more, meaning 5, 10, 15gbit of inbound traffic simply meant to overwhelm equipment/routers/etc. This is fairly easily filtered by large hosts, and DDoS filtering companies. It's simply a matter of having more network and hardware capacity than the attackers.

The harder to filter stuff are HTTP based attacks that appear to be "legit" traffic hitting specifc applications. They may simply make get requests for pages that have high overhead, or actually follow a transaction model. However, companies where DDoS is their business absolutely do have means to protect against this. It's not cheap, and isn't easy, but it is possible if your downtime is worth more than the cost to stay up. Many mechanisms exist, but generally since HTTP attacks cannot be spoofed they revolve around watching all connections, when one IP is seen too much they get redirected to a capchta based system of some sort. If the attack still is working, all traffic can be redirected. Yes, this does have an effect on your traffic of course - but it's better than being 100&#37; down. There are also multitudes of other ways.

In short, I wouldn't just lay down and give up. DDoS sucks, is expensive as hell to filter, but it is possible if given enough equipment, capacity, and knowledge. However, there may simply be a point where it's cheaper to leave sites down a for a few days or a week, than pay an easy 6 figures to filter them for that time period.

Good luck to everyone involved!

-Phil

gero 06-03-2007 03:58 PM

Quote:

Originally Posted by SmokeyTheBear (Post 12537336)
Just curious what brought this about , usually its when a mailer doesnt get paid..:winkwink:

I wish it would be the issue, at least we would know someone who hates us bad. But we never spam and use mailers.

gero 06-03-2007 04:01 PM

Quote:

Originally Posted by kaori (Post 12537418)
hahah - yeah, like this guy?? Spam I found in my email box today...

Yeah, guess what, I got this spam as well, not only this but tonnes of similar ones with copy-pasted text from our websites. I can only stress it, we never ever spam.

gero 06-03-2007 04:05 PM

Quote:

Originally Posted by SmokeyTheBear (Post 12537445)
lol your one step ahead of me i was just gonna go look in my inbox and see if i had spam from them, that usually explains it..

once you get in bed with these guys its hard to get back out of bed , especially when your holding the loot lol

anyways hopefully the problems get fixed , and hopefully people/sponsors will take this thread in mind .. if you deal with unethical people or in an unethical manner it comes back to bite you in the ass.

Now this whole thing might just be coincidence , but when a sponsor is getting ddos its usually mailers and they usually have a reason :)

lets hope this is an isolated problem

We never hired spammers. We never hired anybody with unethical manners. NEVER and WILL NEVER DO THAT.

Might it be a reason for this attack if we banned spammers from our program due to the fact that it's clearly stated in our terms, that we have ZERO TOLERANCE TOWARDS SPAM?

gero 06-03-2007 04:07 PM

Quote:

Originally Posted by zargan (Post 12537592)
DDOS at the application level or network level ? ... it is a BIG difference because 21sextury cash can stop the application level attacks but if there it is a network attack only ISP should stop this

The attack we got is BOTH, application and network level.

gero 06-03-2007 04:20 PM

Anyways what I couldn't understand when I got this spam as well, that why it is not having a referral code? I mean what is the reason for anybody to send out spams - without being asked/hired/anything - for our websites, just having the pure domain in it? Can it be a part of a process to destroy our image?

kaori 06-03-2007 04:21 PM

Quote:

Originally Posted by gero (Post 12537658)
Yeah, guess what, I got this spam as well, not only this but tonnes of similar ones with copy-pasted text from our websites. I can only stress it, we never ever spam.

yeah - was gonna say I got a bunch of other ones like that in my inbox..
glad you don't support them..

gero 06-03-2007 04:24 PM

Because if it is, then it's pretty smart. I was pissed of myself getting these spams at least 15times a day. After this anybody on Earth can be so pissed of to ddos us.

gero 06-03-2007 04:32 PM

Quote:

Originally Posted by kaori (Post 12537746)
yeah - was gonna say I got a bunch of other ones like that in my inbox..
glad you don't support them..

That's why it's so strange. Why would anybody want to send out spam if they don't profit from it? Only reason can be to hurt somebody, right now us. :(

gero 06-03-2007 04:36 PM

CAN PLEASE ANYBODY WHO GOT THIS SPAM, SEND THE MAIL HEADER TO sales aT 21sextury d0t com

Jace 06-03-2007 04:45 PM

gero, seriously, I have rethought this, and if this is important enough and if you all are serious about your business....hire prolexic

they will stop everything coming to you, they will take the heat and pass of the leftover to you..it is quite cool to see how their shit work, I have a very close friend that is a pretty high level tech there

they are expensive, and it will cost you $6-10k

Quote:

[17:10] guy from prolexic: we have customers that pay ~30k+ a month and when they go down, even for a minute, you best believe they scream
Quote:

[16:59] guy from prolexic: he can sign up for prolexic services if he wants, but we're going to charge him 3-5k+ a month

Jace 06-03-2007 04:46 PM

Quote:

Originally Posted by gero (Post 12537739)
Anyways what I couldn't understand when I got this spam as well, that why it is not having a referral code? I mean what is the reason for anybody to send out spams - without being asked/hired/anything - for our websites, just having the pure domain in it? Can it be a part of a process to destroy our image?

because someone probably pasted it straight from their inbox and didn't paste the source

I get thousands of spam a day, I am doing a search in my deleted items now for something for you

Miguel T 06-03-2007 04:50 PM

That sucks big time :(

gero 06-03-2007 04:53 PM

Quote:

Originally Posted by Jace (Post 12537820)
gero, seriously, I have rethought this, and if this is important enough and if you all are serious about your business....hire prolexic

they will stop everything coming to you, they will take the heat and pass of the leftover to you..it is quite cool to see how their shit work, I have a very close friend that is a pretty high level tech there

they are expensive, and it will cost you $6-10k

We have already contacted them. Also other solution providers for ddos. It was not a question to contact them. This was the first thing once we read about them here. I'm afraid the quote is going to be more a six figure quote, not 10K.

Jace 06-03-2007 04:54 PM

Quote:

Originally Posted by gero (Post 12537850)
We have already contacted them. Also other solution providers for ddos. It was not a question to contact them. This was the first thing once we read about them here. I'm afraid the quote is going to be more a six figure quote, not 10K.

oh wow, holy shit

sounds like they want a contract up front guaranteeing them a certain time period of coverage

Jace 06-03-2007 06:58 PM

hey gero, glad talking with my buddy worked out...wish I had some influence on their pricing, but I guarantee once they tap into it you will be back up

kaori 06-03-2007 07:07 PM

Quote:

Originally Posted by gero (Post 12537793)
CAN PLEASE ANYBODY WHO GOT THIS SPAM, SEND THE MAIL HEADER TO sales aT 21sextury d0t com

sent it..
got a few more if you want them too...

gero 06-04-2007 02:03 AM

Quote:

Originally Posted by kaori (Post 12538377)
sent it..
got a few more if you want them too...

Thanks, please send more.

gero 06-04-2007 02:04 AM

In the mean time we contracted prolexic. They guaranteed to put us back up in 24hrs.


All times are GMT -7. The time now is 05:17 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123